Overview
A remote desktop app in Cloudraw can show one of two things:
- Full desktop: people see the whole Windows desktop of the server, with the Start menu and every program on it.
- One program (RemoteApp): people see only one program, for example Excel or your accounting app, in its own window. They do not see the desktop.
One program is a good fit when people need a single line-of-business app and nothing else on that server.
Why Windows needs a one-time setup
Windows opens a program as a RemoteApp only if that program is on the server's RemoteApp allow-list. A program that is not on the list is refused. Cloudraw gives you a short PowerShell command that adds your program to the list. You run it once per program. The allow-list itself stays on, so only the programs you add can open this way.
The same server can also be published as a full desktop. The full desktop and each single program are separate apps in Cloudraw, each with its own access rules.
What the server needs
- Windows Server, or Windows 10 or 11 Pro or Enterprise.
- Remote Desktop turned on on that computer.
- The program installed on that computer.
- A Cloudraw connector that can reach the computer on its Remote Desktop port (usually 3389).
- An administrator account on the computer, to run the one-time setup.
You do not need the Remote Desktop Services (RDS) role or an RD Session Host. Cloudraw makes the same allow-list entry that RDS publishing would make.
Windows 10 and 11 allow one remote session at a time. If someone is signed in at the computer itself, a RemoteApp session can sign them out. For more than one user at a time, use Windows Server.
Step 1. Publish the program
You can publish a new program in one step, or turn an existing remote desktop app into one program.
New app
- Start a new applicationIn the Cloudraw admin console go to Applications→New application and choose One program (RemoteApp).
- Fill in the fieldsUse the table below.
- CreateCloudraw creates the app, sets the program and turns on browser access in one go. The Prepare the server — one time box appears right away. Go on to step 2.
| Field | What to enter |
|---|---|
| Name | What people see in the portal, for example Accounting. |
| Server | The computer's name or IP address, and its Remote Desktop port (3389 unless you changed it). |
| Program | The program to open. See the next table. |
| Connector | The Cloudraw connector that can reach this computer. |
Existing remote desktop app
Open the app page. Under Show, change Full desktop to One app (RemoteApp), type the program and save. Browser access must be on for this app. Under Advanced you can also set a start folder and command-line arguments.
What to type as the program
| You type | When to use it |
|---|---|
notepad.exe | A program that Windows can find by name (it is on the system path). |
excel | A program registered with Windows under a short name. Office programs usually are. |
C:\Program Files\App\app.exe | Any other program. Type the full path, without quotes, even if it has spaces. |
||name | A RemoteApp you already published on the server yourself (for example with RD Session Host). Type two vertical bars and its alias. Cloudraw uses it as it is, and there is no setup to run. |
The program can be up to 260 characters long. It cannot contain quotes or line breaks.
Step 2. Prepare the server (one time)
After you save a program (anything except a ||name alias), the app page shows the Prepare the server — one time box with a command to copy.
- Open PowerShell as AdministratorSign in to the server itself (not your own computer). Right-click Windows PowerShell and choose Run as administrator.
- Paste the commandCopy the command from the box and press Enter. It looks like this: [Net.ServicePointManager]::SecurityProtocol = 'Tls12'; iex (irm 'https://orchestrator-stg.cloudraw.com/pub/remote-app-setup/<app id>/<token>.ps1') Always copy it from your console. Each program has its own link.
- Check the resultPowerShell prints a green line such as "Ready: Accounting (C:\Program Files\App\app.exe) can now open from Cloudraw as a single app."
- Check the consoleThe box on the app page changes to Server ready, with the computer name and the time. Then click Test in browser.
What the command changes
The command changes only one thing: it adds one entry to the RemoteApp allow-list, at this registry key:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList\Applications\cloudraw-<app>cloudraw-<app>is made from your app's name in Cloudraw, for examplecloudraw-accounting.- The entry holds the program's display name, its full path and its icon. It is hidden from RD Web Access.
- It allows the start folder and arguments you set in Cloudraw to be passed to the program.
- The allow-list stays on. Other programs are still refused.
Before it writes anything, the command checks that it runs as Administrator and finds the full path of the program. It looks for the exact path you typed, then the system path, then the programs registered with Windows. When it is done, it tells Cloudraw, so the console can show Server ready.
Want to read the script first? The console also shows the link to the full script. Open it in a browser. It is plain text.
Servers without internet
The command downloads the script from Cloudraw and reports back to Cloudraw. If the server has no internet access:
- Open the full script link on another computer and copy the script to the server.
- Run it in PowerShell as Administrator. It prints "Note: could not tell Cloudraw the setup is done (no internet?). Mark it done on the app page." That is expected.
- On the app page, click I did it by hand — mark as ready.
Use the same link if you add the registry entry another way, for example with a Group Policy.
If you change the program, Cloudraw makes a new setup link and the old link stops working. Run the new command on the server. If you save the same program again, nothing changes and the setup stays done.
Automatic setup by the connector
If the Cloudraw connector runs on the same Windows server as the program, you do not need to paste anything. The connector does the setup by itself:
- It adds each program you publish on that server to the RemoteApp allow-list, using the same
cloudraw-<app>entries. - It never touches allow-list entries that do not start with
cloudraw-. - It reports back, so the app page shows Server ready on its own.
- It lists the programs installed on the server, so you can pick the program from a list instead of typing it.
This needs the Windows connector, build b11 or newer. It works when the app's server address is the connector's own computer: localhost, 127.0.0.1, or the connector computer's name.
The helper is on by default. You can turn it off on the connector's page with the RemoteApp helper switch. Then use the command from step 2 instead.
If the program list is empty, the connector has not listed its programs yet. It does so within a few minutes. You can always type the program instead.
How people open it
A RemoteApp opens in the Cloudraw portal, in the browser, through the Cloudraw browser gateway. People do not need to install anything for it.
- Open the portalThe person signs in to your workspace's Cloudraw portal and clicks the app's tile. They see the tile only if an access rule gives them the app.
- Sign in to the serverCloudraw asks for their Windows user name, password and, if needed, domain for that computer. Cloudraw uses these only to start this session. It never stores them.
- Work in the programOnly the program opens, in a new tab or window. The desktop is not shown.
- Recording: if you turned on recording for this app, the session is recorded. If you also turned on the recording notice, people first see a short page, by default "This session is recorded for security and compliance.", and click Continue.
- Clipboard and devices: the app's settings for copy and paste, printers, microphone and audio apply. Copy out and paste in are off unless you allow them for the app.
- Icon: on the app page you can upload the program's own icon, so the portal tile looks like the program.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
| Portal: "<App> needs a one-time setup on its server before it can open. Your IT admin will find the command on the app page in Cloudraw." | The setup has not reported back yet. Run the command from step 2 on the server. If the server has no internet, click mark as ready after you ran it. Admins who open the app in the portal also see the command there. |
| PowerShell: "Could not find X on this server. In Cloudraw, type its full path instead (for example C:\Program Files\App\app.exe)." | Windows does not know the program by that name, or you ran the command on a different computer. Type the full path in Cloudraw, save, and run the new command on the server. |
| PowerShell: "Run this in PowerShell as Administrator." | Close PowerShell, right-click it and choose Run as administrator. |
| PowerShell: "this setup link is not valid any more. Copy a fresh command from the app page." | The program was changed after you copied the command. Copy the new command from the app page. |
| PowerShell: "Note: could not tell Cloudraw the setup is done (no internet?)" | The program was added, but the server cannot reach Cloudraw. Click mark as ready on the app page. |
| The session ends with a message that the remote computer or RDP server is unavailable | Windows refused the program. Check that the key TSAppAllowList\Applications\cloudraw-<app> exists on the server and that its path still points to the program, for example after an upgrade moved it. For a ||name alias, check that it is really published on the server. Also check that Remote Desktop is on and the connector can reach port 3389. |
| The connector helper shows an error on the app page | The connector could not register the program, often because the program was not found. Type the full path, or turn off the helper and use the command. |
| Portal: "Browser access for this app is being prepared. Try again in a minute." | Browser access was just turned on. Wait a minute and try again. |
| Console: "RemoteApp applies to remote desktop (RDP) apps only." | One program works only for remote desktop apps, not for SSH, VNC, websites or file shares. |
| Console: "a RemoteApp alias like ||notepad or a program path (max 260 characters)" | The program field is empty, too long, or has quotes. Type the path without quotes. |